bff-entry-points
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a high-quality security reference for designing and protecting HTTP entry points, following industry standards such as OWASP ASVS and IETF RFCs.\n- [SAFE]: Implementation examples demonstrate secure coding practices using well-known libraries like Hono and Zod, specifically addressing CSRF, Origin verification, and Fetch Metadata policy.\n- [SAFE]: The skill includes robust logic for preventing open redirects and protecting realtime streams (SSE/WebSockets), ensuring authentication and authorization happen before resource allocation.\n- [SAFE]: No obfuscation, hardcoded credentials, malicious persistence mechanisms, or unauthorized network operations were detected.
Audit Metadata